Displaying 2 results from an estimated 2 matches for "administrt".
Did you mean:
administra
2016 Dec 18
2
Extend logging of openssh-server - e.g. plaintext password
...example.com" in my local DNS,
* The new admin at work, unaware of this "we don't allow PassPhrase
based access", tries to log into "www.example.com".
* The new admin uses his password. Having difficulty logging into the
honeypot, he then tries to log in as root or other administrtive
accounts.
* The honeypoyt now has copies of the login names, and passphrases,
stored in cleartext, without having to modify a single line of their
OpenSSH source code or a single byte of their binary.
* Voila: stashed passphrases and login names for the deired "www.example.com".
The p...
2016 Dec 18
2
Extend logging of openssh-server - e.g. plaintext password
I concur with Nico ? logging plaintext passwords is an extremely bad idea.
The tone of the poster also leaves much to be desired ? but I?ll hold my tongue for now.
--
Regards,
Uri Blumenthal
On 12/18/16, 11:48, "openssh-unix-dev on behalf of Nico Kadel-Garcia" <openssh-unix-dev-bounces+uri=ll.mit.edu at mindrot.org on behalf of nkadel at gmail.com> wrote:
On Sun, Dec 18,